Skip to content

Commit

Permalink
use manual line-wrapping because ansible-lint does not support it cor…
Browse files Browse the repository at this point in the history
…rectly.

see ansible/ansible-lint#2522

Signed-off-by: Sebastian Gumprich <sebastian.gumprich@t-systems.com>
  • Loading branch information
Sebastian Gumprich committed Nov 29, 2022
1 parent ad9ccd8 commit 684f159
Showing 1 changed file with 24 additions and 8 deletions.
32 changes: 24 additions & 8 deletions roles/mysql_hardening/tasks/mysql_secure_installation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,17 +36,27 @@

- name: Ensure that root can only login from localhost
community.mysql.mysql_query:
query:
- DELETE FROM mysql.user WHERE USER='root' AND HOST NOT IN ('localhost', '127.0.0.1', '::1')
query: >
DELETE
FROM mysql.user
WHERE USER='root'
AND HOST NOT IN ('localhost',
'127.0.0.1',
'::1');
login_unix_socket: "{{ login_unix_socket | default(omit) }}"
when: mysql_remove_remote_root

- name: Get all users that have no authentication_string on MySQL version >= 5.7.6 or Mariadb version >= 10.4.0
community.mysql.mysql_query:
query: >
SELECT GROUP_CONCAT(QUOTE(USER), '@', QUOTE(HOST) SEPARATOR ', ') AS users FROM mysql.user
WHERE (length(authentication_string)=0 OR authentication_string="")
AND USER NOT IN ('mysql.sys', 'mysqlxsys', 'mariadb.sys');
SELECT GROUP_CONCAT(QUOTE(USER), '@', QUOTE(HOST) SEPARATOR ', ') AS users
FROM mysql.user
WHERE (length(authentication_string)=0
OR authentication_string="")
AND USER NOT IN ('mysql.sys',
'mysqlxsys',
'mariadb.sys');
login_unix_socket: "{{ login_unix_socket | default(omit) }}"
register: mysql_users_wo_passwords_or_auth_string
when: >
Expand All @@ -57,9 +67,15 @@
- name: Get all users that have no password or authentication_string on MySQL version < 5.7.6 or Mariadb version < 10.4.0
community.mysql.mysql_query:
query: >
SELECT GROUP_CONCAT(QUOTE(USER), '@', QUOTE(HOST) SEPARATOR ', ') AS users FROM mysql.user
WHERE (length(password)=0 OR password="") AND (length(authentication_string)=0
OR authentication_string="") AND USER NOT IN ('mysql.sys', 'mysqlxsys', 'mariadb.sys');
SELECT GROUP_CONCAT(QUOTE(USER), '@', QUOTE(HOST) SEPARATOR ', ') AS users
FROM mysql.user
WHERE (length(password)=0
OR password="")
AND (length(authentication_string)=0
OR authentication_string="")
AND USER NOT IN ('mysql.sys',
'mysqlxsys',
'mariadb.sys');
login_unix_socket: "{{ login_unix_socket | default(omit) }}"
register: mysql_users_wo_passwords
when: >
Expand Down

0 comments on commit 684f159

Please sign in to comment.